CVE-2020-9700 is a buffer error vulnerability affecting multiple versions of Adobe Acrobat and Reader across Adobe, Apple, and Microsoft platforms. This high-severity flaw (CVSS 7.8) can be exploited with low complexity through user interaction, potentially leading to arbitrary code execution with high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, the vulnerability has received media coverage and community discussion, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 20.009.20074CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30171CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
20.001.30002CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:20.001.30002:*:*:*:classic:*:*:* | ||
>= 15.006.30060, <= 15.006.30523CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.